Privacy policy

Your data, in plain English.

Last updated: 29 May 2026

Who we are

theHRkey is an AI-native HR & resourcing practice operated by Ali Akeel, sole trader, based in the United Kingdom. We are the data controller for any personal data you submit through this site. Reach us at info@thehrkey.com.

What we collect

Why we collect it

Lawful basis (UK GDPR)

Who we share data with

How long we keep it

Each period runs from your last activity with us, not from when we first collected something.

WhatHow longWhy that long
Your profile and CV24 months after your last activity So we can keep putting you forward without asking you to start again. Delete it sooner at any time.
Records of roles we discussed with you, and who we approachedAt least 12 months Required of employment agencies by the Conduct of Employment Agencies and Employment Businesses Regulations 2003.
Placement and invoice records6 years Accounting and tax obligations where a fee was charged.
Chat transcripts24 monthsTo answer follow-up questions and improve the service.
A record that you asked not to be contactedKept indefinitely It is the only thing stopping us contacting you again. See below.
Anonymous analytics14 monthsProvider default.

What we send to Google's Gemini API

We do not send your CV to Google. CVs are read on our own server and stay there. We use Gemini for three narrow things:

Under the Gemini API terms this content is not used to train Google's models. If you would rather nothing you write is processed this way, say so in your message and we will handle it by hand.

How we share you with an employer

We do not give an employer your name, email address or phone number. When we put you forward, they see an anonymised profile — your experience, skills and general location under a reference such as C-4170 — and only for a role you have specifically approved. If they want to meet you, we arrange the interview ourselves. Your contact details stay with us throughout.

We keep a record of every time your details were shared, with whom, and on what basis. You can ask to see that record.

Your rights

Under UK GDPR you have the right to:

Email info@thehrkey.com with the request. We respond within one calendar month, as UK GDPR requires. We may ask you to confirm your identity first — we are not going to hand your record to whoever asks for it.

What we cannot delete, and why

If you ask us to erase you, we remove your profile, your CV, your consents, your applications, your alert subscriptions and the content of our correspondence. Two things deliberately survive, and we would rather say so plainly than surprise you:

We will tell you which of these applied to you when we confirm the erasure.

Security

We keep a nightly backup so your record survives a fault. It is encrypted with AES-256 before it leaves the server, and a copy is held in a private GitHub repository so one failure cannot lose everything. The key is not stored with the backups and not held by GitHub. Only the last 7 nights are kept off-site, and the whole set is replaced each night rather than added to — so if you ask us to erase you, you disappear from the backups too, within a week, instead of remaining in a history forever.

The site runs over TLS. Passwords are hashed with bcrypt (cost 12). CVs are stored above the web root so they can't be served accidentally. Access to the server is restricted to key-based SSH. We don't keep payment card data — that lives with our payment processor.

Cookies

See the cookie policy for the full list and how to change your mind.

Changes to this policy

If we make material changes we'll flag them on the homepage for at least 14 days and email anyone who has an account.